OS Command Injection Vulnerability in Planet WGR-500 Router
CVE-2025-54405
8.8HIGH
What is CVE-2025-54405?
The Planet WGR-500 router is susceptible to multiple OS command injection vulnerabilities due to flaws in the formPingCmd functionality. By crafting specific HTTP requests, an attacker can exploit the vulnerability related to the ipaddr
request parameter, allowing for arbitrary command execution on the device. This security gap poses significant risks, enabling unauthorized actions that can compromise the integrity and availability of the network.
Affected Version(s)
WGR-500 v1.3411b190912